Air-gapped Appliance Installation

Use this path when Management cannot reach the source registry. Download the required files on a connected workstation and transfer them into the isolated environment. This works with either Management deployment option.

Prepare Files on a connected Workstation

Required material How to obtain it

Management, if not already deployed

Choose the Management ISO and checksum or Management container image archive. Container deployments also need a prepared runtime and, for Docker Compose, its configuration files.

Full Appliance release bundle

Use Export bundle archives to pull the release image and save it as an OCI archive. Select the destination Management engine’s architecture. A fresh installation does not need an update bundle.

Appliance boot media and checksum

Download the boot artifact for the intended Appliance release, hypervisor and guest-agent choice.

The Management ISO contains Management and its internal services. It does not contain the Appliance release bundle. A Management container archive and a release archive also serve different purposes. Load the Management archive into the host runtime; upload the release archive through the Management web application.

Record the image references and digests. Record SHA-256 checksums for the transferred archives and verify them on arrival. Verify ISO and OVA downloads against their published checksums.

Prepare the isolated Environment

  1. Transfer the required files to the environment. Make the Appliance boot media available to the hypervisor and the release archive available to the operator’s browser.

  2. Provide the planned DNS and NTP services inside the environment and configure the firewall rules.

  3. Deploy Management from the ISO or transferred container image. For Compose, set the loaded image’s tag and MTG_MANAGEMENT_PULL_POLICY=never in .env.

  4. Verify healthy Management status and administrator sign-in.

Upload the Release Bundle

  1. Open Settings > Bundles > Add bundle > Computer > Release or update.

  2. Select the release OCI archive and upload it. Upload the complete bundle image archive with its full tagged image reference.

  3. Wait until Management reports the bundle as available, then verify the intended target release.

Saving a release image into the host’s container image store does not add it to Management’s bundle list. For archive format requirements and Docker commands, see Export bundle archives.

Install from the prepared Files

  1. Follow Install the Appliance and select the locally available release in the installation wizard.

  2. At Download and boot the Talos artifact, compare the requested artifact with the transferred boot media. Check the release, platform and guest-agent choice before proceeding.

  3. Prepare the Proxmox or VMware targets using the transferred media and the per-node network values shown by Management.

  4. Continue with discovery, disk confirmation and installation in Management.

  5. Retain the generated artifact bundle, release archive and boot media outside Management. Then verify the Appliance and initialize ERS.